The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-117: Improper Output Neutralization for Logs, which allows an attacker to create false logs that show the password as having been changed when it is not, complicating forensics.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NCognex 3d A1000 Dimensioning System
HWCognexall versionsCognex 3d A1000 Dimensioning System Firmware
OSCognex≤ 1.0.3\(3354\)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2022-1368CRITICAL9.8PL ✓same product
Brak uwierzytelnienia w Cognex 3D-A1000 umożliwia przejęcie konta
CVE-2022-1525CRITICAL9.1PL ✓same product
Cognex 3D-A1000: Obejście zabezpieczeń webowych przez modyfikację kodu po stronie klienta
CVE-2021-32935HIGH8.8same vendor
The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted da...